Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-08-2013
Ran by XXXXX-XXXXX (administrator) on 21-08-2013 16:02:14
Running from L:\
Microsoft Windows XP Professional Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 6
Boot Mode: Safe Mode (minimal)
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5078504 2013-03-21] (ESET)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k [x]
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... R}&ar=home
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
http://www.yhs.delta-search.com/?q={sea ... l&tsp=4934
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/pub/sh ... wflash.cab
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Tcpip\Parameters: [DhcpNameServer] 85.237.225.250 213.151.200.3
========================== Services (Whitelisted) =================
S2 Ati HotKey Poller; C:\Windows\system32\Ati2evxx.exe [254037 2003-04-28] ()
S4 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [114775 2003-04-28] ()
S2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [1341664 2013-03-21] (ESET)
S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S4 VRAID Log Service; C:\Program Files\VIA\RAID\vialogsv.exe [52888 2008-09-24] ()
S2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
==================== Drivers (Whitelisted) ====================
S3 ALCXWDM; C:\Windows\System32\drivers\ALCXWDM.SYS [4108992 2007-08-07] (Realtek Semiconductor Corp.)
S1 eamon; C:\Windows\System32\DRIVERS\eamon.sys [161368 2013-01-10] (ESET)
S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [122240 2013-01-10] (ESET)
S1 epfwtdir; C:\Windows\System32\DRIVERS\epfwtdir.sys [105784 2013-01-10] (ESET)
S1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [73728 2008-05-24] (EZB Systems, Inc.)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [35144 2013-08-20] ()
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 nvax; C:\Windows\System32\drivers\nvax.sys [13056 2002-12-05] (NVIDIA Corporation)
S3 NVENET; C:\Windows\System32\DRIVERS\NVENET.sys [80896 2002-09-23] (NVIDIA Corporation)
S3 nvnforce; C:\Windows\System32\drivers\nvapu.sys [241664 2002-12-05] (NVIDIA Corporation)
R0 nv_agp; C:\Windows\System32\DRIVERS\nv_agp.sys [13568 2002-09-06] (NVIDIA Corporation)
S2 Secdrv; C:\Windows\System32\DRIVERS\secdrv.sys [27440 2004-07-17] ()
R0 viamraid; C:\Windows\System32\DRIVERS\viamraid.sys [117248 2008-07-09] (VIA Technologies inc,.ltd)
S3 catchme; \??\C:\DOCUME~1\XXXXX-~1\LOCALS~1\Temp\catchme.sys [x]
S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [x]
S4 IntelIde; No ImagePath
S3 NTACCESS; \??\F:\NTACCESS.sys [x]
S3 SetupNTGLM7X; \??\F:\NTGLM7X.sys [x]
S3 xcqadj; \??\C:\WINDOWS\system32\01.tmp [x]
==================== NetSvcs (Whitelisted) ===================
NETSVC: hkskqyew -> No Registry Path.
==================== One Month Created Files and Folders ========
2013-08-21 15:28 - 2013-08-21 15:28 - 01070183 _____ (Farbar) C:\FRST.exe
2013-08-21 14:41 - 2013-08-21 14:41 - 00090112 _____ C:\WINDOWS\Minidump\Mini082113-01.dmp
2013-08-20 21:52 - 2013-02-08 00:49 - 07622112 _____ (Malwarebytes Corporation ) C:\Documents and Settings\XXXXX-XXXXX\Desktop\mbam-setup.exe
2013-08-20 21:33 - 2013-08-20 21:33 - 00000784 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-20 21:33 - 2013-08-20 21:33 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-20 21:33 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-08-20 21:32 - 2013-08-20 21:32 - 10285040 _____ (Malwarebytes Corporation ) C:\Documents and Settings\XXXXX-XXXXX\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-20 21:19 - 2013-08-20 21:27 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Desktop\mbar
2013-08-20 21:19 - 2013-08-20 21:19 - 00035144 _____ C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2013-08-20 21:18 - 2013-08-20 21:19 - 12081912 _____ (Malwarebytes Corp.) C:\Documents and Settings\XXXXX-XXXXX\Desktop\mbar-1.06.1.1005.exe
2013-08-19 20:03 - 2013-08-21 15:59 - 00013724 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-19 19:57 - 2013-08-19 19:57 - 00007381 _____ C:\ComboFix.txt
2013-08-19 19:07 - 2013-08-19 19:07 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Application Data\Malwarebytes
2013-08-19 19:07 - 2013-08-19 19:07 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-08-03 21:07 - 2004-08-04 00:56 - 00010752 ____N (Microsoft Corporation) C:\WINDOWS\system32\smtpapi.dll
2013-08-03 21:07 - 2004-08-04 00:56 - 00009728 ____N (Microsoft Corporation) C:\WINDOWS\system32\rwnh.dll
2013-08-02 20:39 - 2004-08-03 23:01 - 00025856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbprint.sys
2013-08-02 20:39 - 2004-08-03 23:01 - 00025856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbprint.sys
2013-07-23 08:42 - 2013-07-23 08:42 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Application Data\ML
2013-07-23 08:38 - 2013-07-23 08:38 - 00000000 ____D C:\WINDOWS\MetaUSBDriver
2013-07-23 08:38 - 2013-07-23 08:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\iRiver
2013-07-23 08:36 - 2013-07-23 08:38 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\My Documents\Iriver Plus4
2013-07-23 08:36 - 2013-07-23 08:36 - 00003565 _____ C:\aqua_bitmap.cpp
2013-07-23 08:35 - 2013-07-23 08:35 - 01286152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml4.dll
2013-07-23 08:35 - 2013-07-23 08:35 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml4r.dll
==================== One Month Modified Files and Folders =======
2013-08-21 15:59 - 2013-08-19 20:03 - 00013724 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-21 15:59 - 2013-02-08 19:19 - 00000430 _____ C:\WINDOWS\wincmd.ini
2013-08-21 15:59 - 2013-02-07 14:53 - 00000178 ___SH C:\Documents and Settings\XXXXX-XXXXX\ntuser.ini
2013-08-21 15:40 - 2013-02-12 18:09 - 00154875 _____ C:\PollSt.txt
2013-08-21 15:40 - 2013-02-07 15:10 - 00000000 __SHD C:\WINDOWS\CSC
2013-08-21 15:40 - 2013-02-07 14:50 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-21 15:28 - 2013-08-21 15:28 - 01070183 _____ (Farbar) C:\FRST.exe
2013-08-21 14:41 - 2013-08-21 14:41 - 00090112 _____ C:\WINDOWS\Minidump\Mini082113-01.dmp
2013-08-20 22:36 - 2013-02-07 14:53 - 00032610 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-20 21:33 - 2013-08-20 21:33 - 00000784 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-20 21:33 - 2013-08-20 21:33 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-20 21:32 - 2013-08-20 21:32 - 10285040 _____ (Malwarebytes Corporation ) C:\Documents and Settings\XXXXX-XXXXX\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-20 21:27 - 2013-08-20 21:19 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Desktop\mbar
2013-08-20 21:27 - 2013-02-07 14:48 - 00000000 ____D C:\WINDOWS\srchasst
2013-08-20 21:19 - 2013-08-20 21:19 - 00035144 _____ C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2013-08-20 21:19 - 2013-08-20 21:18 - 12081912 _____ (Malwarebytes Corp.) C:\Documents and Settings\XXXXX-XXXXX\Desktop\mbar-1.06.1.1005.exe
2013-08-19 19:58 - 2013-02-09 01:12 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Application Data\uTorrent
2013-08-19 19:58 - 2013-02-09 00:57 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Application Data\Winamp
2013-08-19 19:58 - 2013-02-08 20:29 - 00000000 ____D C:\WINDOWS\Minidump
2013-08-19 19:58 - 2013-02-08 19:28 - 00000000 ___SD C:\Documents and Settings\XXXXX-XXXXX\UserData
2013-08-19 19:58 - 2013-02-07 14:53 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX
2013-08-19 19:58 - 2013-02-07 14:48 - 00000000 ____D C:\WINDOWS\system32\Restore
2013-08-19 19:57 - 2013-08-19 19:57 - 00007381 _____ C:\ComboFix.txt
2013-08-19 19:57 - 2013-02-10 01:16 - 00000000 ____D C:\Qoobox
2013-08-19 19:56 - 2001-08-23 14:00 - 00000262 _____ C:\WINDOWS\system.ini
2013-08-19 19:47 - 2013-02-10 01:15 - 05105821 ____R (Swearware) C:\Documents and Settings\XXXXX-XXXXX\Desktop\ComboFix.exe
2013-08-19 19:07 - 2013-08-19 19:07 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Application Data\Malwarebytes
2013-08-19 19:07 - 2013-08-19 19:07 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-08-16 21:51 - 2013-07-07 20:12 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Local Settings\Application Data\NFS Underground 2
2013-08-14 16:49 - 2013-06-01 23:16 - 00000000 ____D C:\Program Files\PokerStars
2013-08-13 17:19 - 2013-02-07 14:53 - 00000000 __SHD C:\Documents and Settings\NetworkService
2013-08-13 16:09 - 2013-02-10 15:26 - 00000000 ____D C:\Program Files\ESET
2013-08-12 17:55 - 2013-03-26 16:32 - 00692104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-08-12 17:55 - 2013-03-26 16:32 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-08-12 17:55 - 2013-02-08 19:23 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Local Settings\Application Data\Adobe
2013-08-03 21:09 - 2013-02-07 16:07 - 00000249 _____ C:\WINDOWS\system32\spupdwxp.log
2013-08-03 21:09 - 2013-02-07 16:03 - 00316640 _____ C:\WINDOWS\WMSysPr9.prx
2013-08-03 21:09 - 2013-02-07 14:53 - 00000792 _____ C:\Documents and Settings\XXXXX-XXXXX\Start Menu\Programs\Windows Media Player.lnk
2013-08-03 21:09 - 2001-08-23 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-03 21:08 - 2013-02-11 15:34 - 00000000 ____D C:\WINDOWS\security
2013-08-03 21:07 - 2013-02-11 15:38 - 00000327 __RSH C:\boot.ini
2013-08-03 21:07 - 2013-02-11 15:34 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2013-07-28 22:32 - 2013-07-16 21:32 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\My Documents\Syberia Saves
2013-07-25 22:14 - 2013-02-07 14:56 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-07-23 08:42 - 2013-07-23 08:42 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Application Data\ML
2013-07-23 08:38 - 2013-07-23 08:38 - 00000000 ____D C:\WINDOWS\MetaUSBDriver
2013-07-23 08:38 - 2013-07-23 08:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\iRiver
2013-07-23 08:38 - 2013-07-23 08:36 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\My Documents\Iriver Plus4
2013-07-23 08:36 - 2013-07-23 08:36 - 00003565 _____ C:\aqua_bitmap.cpp
2013-07-23 08:35 - 2013-07-23 08:35 - 01286152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml4.dll
2013-07-23 08:35 - 2013-07-23 08:35 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml4r.dll
2013-07-23 08:35 - 2013-02-08 19:54 - 00000000 ____D C:\Documents and Settings\XXXXX-XXXXX\Local Settings\Application Data\Downloaded Installations
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2013-02-07 15:58] - [2004-08-04 01:56] - 1032192 ____A (Microsoft Corporation) a0732187050030ae399b241436565e64
C:\Windows\System32\winlogon.exe
[2013-02-07 15:58] - [2004-08-04 01:56] - 0502272 ____A (Microsoft Corporation) 01c3346c241652f43aed8e2149881bfe
C:\Windows\System32\svchost.exe
[2013-02-07 15:58] - [2004-08-04 01:56] - 0014336 ____A (Microsoft Corporation) 8f078ae4ed187aaabc0a305146de6716
C:\Windows\System32\services.exe
[2013-02-07 15:58] - [2004-08-04 01:56] - 0108032 ____A (Microsoft Corporation) c6ce6eec82f187615d1002bb3bb50ed4
C:\Windows\System32\User32.dll
[2013-02-07 15:58] - [2004-08-04 01:56] - 0577024 ____A (Microsoft Corporation) c72661f8552ace7c5c85e16a3cf505c4
C:\Windows\System32\userinit.exe
[2013-02-07 15:58] - [2004-08-04 01:56] - 0024576 ____A (Microsoft Corporation) 39b1ffb03c2296323832acbae50d2aff
C:\Windows\System32\Drivers\volsnap.sys
[2013-02-07 15:58] - [2004-08-04 00:00] - 0052352 ____A (Microsoft Corporation) ee4660083deba849ff6c485d944b379b
==================== End Of Log ============================